MOVEit Transfer CVE-2023-34362 Deep Dive and Indicators of Compromise

MOVEit Transfer CVE-2023-34362 Deep Dive and Indicators of Compromise

| | Blog, Red Team
On May 31, 2023, Progress released a security advisory for their MOVEit Transfer application which detailed a SQL injection leading to remote code execution and urged customers to update to the latest version. The vulnerability, CVE-2023-34362, at the time of release was believed to have been exploited in-the-wild as a ... Read More
PaperCut CVE-2023-27350 Deep Dive and Indicators of Compromise

PaperCut CVE-2023-27350 Deep Dive and Indicators of Compromise

| | Blog, Red Team
Overview On 8 March 2023, PaperCut released new versions for their enterprise print management software, which included patches for two vulnerabilities: CVE-2023-27350 and CVE-2023-27351. The PaperCut security advisory details CVE-2023-27350 as a vulnerability that may allow an attacker to achieve remote code execution to compromise the PaperCut application server. PaperCut ... Read More
Fortinet FortiNAC CVE-2022-39952 Deep-Dive and IOCs

Fortinet FortiNAC CVE-2022-39952 Deep-Dive and IOCs

| | Blog, Red Team
Introduction On Thursday, 16 February 2022, Fortinet released a PSIRT that details CVE-2022-39952, a critical vulnerability affecting its FortiNAC product. This vulnerability, discovered by Gwendal Guégniaud of Fortinet, allows an unauthenticated attacker to write arbitrary files on the system and as a result obtain remote code execution in the context ... Read More
Best of 2022: OpenSSL Critical Vulnerability: Should You Be Spooked?

Best of 2022: OpenSSL Critical Vulnerability: Should You Be Spooked?

| | Blog, Red Team
On Tuesday, October 25 a new OpenSSL hot-fix release was announced which will patch a critical vulnerability that exists within the v3.0.X branch. OpenSSL 3.0.7 will be released on Tuesday, November 1 and in tandem the details of the vulnerability and its associated CVE will be made public. OpenSSL is ... Read More

Cloud Workload Resilience PulseMeter

Step 1 of 8

How do you define cloud resiliency for cloud workloads? (Select 3)(Required)